Record summary

CVE-2020-35359 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

Pure-FTPd 1.0.48 allows remote attackers to prevent legitimate server use by making enough connections to exceed the connection limit.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Nuclei templates
1

Proofs of concept

1

Catalogued exploits

ExploitDBPure-FTPd 1.0.48 - Remote Denial of ServiceExploitDB exploitby xynmapsNot analyzed1 file
ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryHIGHPure-FTPd 1.0.48 - Denial of ServiceCVSS 7.5

Pure-FTPd 1.0.48 is vulnerable to Denial of Service via exhaustion of connections due to lack of proper connection limits.

Impact

Unauthenticated attackers can exhaust available connections due to lack of proper connection limits, causing denial of service by preventing legitimate users from connecting to the FTP server.

Remediation

Update Pure-FTPd to a version newer than 1.0.48 that implements proper connection limits and rate limiting to prevent connection exhaustion attacks.

WeaknessesCWE-770
Authorspussycat0x
Template tagscvecve2020networkftppure-ftpdtcppassivevuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CPE: cpe:2.3:a:pureftpd:pure-ftpd:1.0.48:*:*:*:*:*:*:*
Shodan: product:"pure-ftpd"
Shodan: cpe:"cpe:2.3:a:pureftpd:pure-ftpd"

Source: ProjectDiscovery

References

2